Start::
CloseProcesses:
SystemRestore: On
CreateRestorePoint:
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
Task: {91267E87-863C-49A1-8753-B8B279039D05} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic (No File)
Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
S3 AppShopDrv103; \??\C:\Windows\SysWOW64\Drivers\AppShopDrv103.sys [X]
S3 HWiNFO_191; \??\C:\Users\BGGAME~1\AppData\Local\Temp\HWiNFO64A_191.SYS [X] <==== ATTENTION
S3 HWiNFO_201; \??\C:\Users\BGGAME~1\AppData\Local\Temp\HWiNFO_x64_201.sys [X] <==== ATTENTION
Task: {E3B85D02-E982-482C-8A89-3E21B0500629} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => C:\Windows\System32\Wscript.exe [204800 2024-07-10] (Microsoft Windows -> Microsoft Corporation) -> C:\Program Files\Intel\SUR\QUEENCREEK\x64\//B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs"
Task: {3AAE6A5F-FE7C-441A-847E-F399AAEAA16B} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [4916640 2024-04-15] (Intel Corporation -> Intel Corporation)
Task: {44C8DB73-DCB7-430B-A8D8-D703A0EEF795} - System32\Tasks\WaterfoxLimited\Waterfox Default Browser Agent 6F940AC27A98DD61 => C:\Program Files\Waterfox\default-browser-agent.exe [678040 2024-07-08] (BrowserWorks Ltd -> Mozilla Foundation)
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini:B1DA6C571C [3434]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ActivityWatch.lnk:FB9FE75D10 [3434]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini:41964AA945 [3434]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epic Games Launcher.lnk:BE32D07BC5 [3434]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FACEIT AC.lnk:550995E265 [3434]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++.lnk:159ADC9AA1 [3434]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Plex Media Server.lnk:A4E18C6AEC [3434]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Waterfox Private Browsing.lnk:14F60F75DA [3434]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Waterfox.lnk:9930A02307 [3434]
FirewallRules: [TCP Query User{60A1A913-DDB6-43C7-B145-DB300E233F6A}D:\ww3\ww3gamelauncher\sglww3.exe] => (Allow) D:\ww3\ww3gamelauncher\sglww3.exe => No File
FirewallRules: [UDP Query User{16C6BDC1-4F38-4DF9-A59F-26FDA516CB47}D:\ww3\ww3gamelauncher\sglww3.exe] => (Allow) D:\ww3\ww3gamelauncher\sglww3.exe => No File
FirewallRules: [{5DBD91D9-4A98-458C-91FB-6A3D1333FD3D}] => (Allow) D:\BlackShot\BlackShot\System\blackshot.exe => No File
FirewallRules: [{9AABA8E3-A321-46B0-ADF8-6CA2D24B2924}] => (Allow) D:\BlackShot\BlackShot\System\blackshot.exe => No File
FirewallRules: [{97B0CBC8-B936-4879-9978-75BF0FA3D8D2}] => (Allow) D:\SteamLibrary\steamapps\common\Albion Online\launcher\AlbionLauncher.exe => No File
FirewallRules: [{D3DB0E55-3343-44A9-A273-734415088197}] => (Allow) D:\SteamLibrary\steamapps\common\Albion Online\launcher\AlbionLauncher.exe => No File
FirewallRules: [{44312121-5C3F-4C0B-ADEC-106FBE9EB283}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\ElementsPanelDaemon.exe => No File
C:\Windows\system32\drivers\etc\hosts
Hosts:
HKU\S-1-5-21-3219355904-1382751206-166821852-1001\...\StartupApproved\Run: => "OneDrive"
CMD: del /s /q "%userprofile%\AppData\Local\temp\*.*"
CMD: ipconfig /flushdns
C:\Windows\Temp\*.*
C:\WINDOWS\system32\*.tmp
C:\WINDOWS\syswow64\*.tmp
emptytemp:
ExportKey: HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions
Reboot:
End::
"C:\Users\*\Documents\Celemony\Separations"="0"
i dont remember what that celemony was or isI really see nothing of concern to be honest.
This was in defender exclusions, any idea what it is?
Code:"C:\Users\*\Documents\Celemony\Separations"="0"
Update everything in red from the Security Check log when you can, uninstall malwarebytes.
If you do not use these:
Uninstall OneDrive.
Disable Bitlocker
Block Edge
ohhhh i wanted to make music so i installed that pluginMelodyne 5 (Version: 5.01.01003 - Celemony Software GmbH) Seems you have this installed.
Things look good, post one last set of FRST and Additon.txt logs to make sure I did not miss anything, I may check them later tonight or tomorrow after work.
also could you help me fix my performance in games too like i want more fps if possible? when we are done with thisOk. I’ll check this tomorrow after work most likely.
Error: (08/07/2024 08:09:37 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Local Hostname bggames.local already in use; will try bggames-2.local instead
Error: (08/07/2024 08:09:37 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: ProbeCount 1; will deregister 16 bggames.local. AAAA FE80:0000:0000:0000:32E8:0A07:D82C:9A9E
Error: (08/07/2024 08:09:37 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from FE80:0000:0000:0000:32E8:0A07:D82C:9A9E:5353 16 bggames.local. AAAA 2603:9000:A300:327E:0000:0000:0000:1E62
We use essential cookies to make this site work, and optional cookies to enhance your experience.